Author: Tekno Phreak


  • Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation

    ![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjohomRDDjZyJfnjTusOWprpUGv8Yf_k2fgvGvfZqhXhusmUz1WWrkZB6yKdDXD1AOxuLmvoK4MJ88QpRBm0L_zRxNchQGVI0Ib3D3piR43BICNq823bHdXod7ADdFLWRfVlp8lChQjgZwNehps4hJf0atYyxanDBDDLLHQgfqLlXhtxbAQ-HyWs-KefebO/s728-rw-e365/main.png)Cybersecurity researchers have uncovered three security weaknesses in Microsoft’s Azure Data Factory [Apache Airflow](https://airflow.apache.org/) integration that, if successfully exploited, could…


  • Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents

    ![U.S. Treasury Systems](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnW4uIKY7rtNoiGYo8nyYHd5Q4GOBJE2Wl-_rkjIV_2niquf9XG2YrD4kttbb6OreSiIdxwiE4vBkrzzBm20bS190-_oo09qmwp2jeTEXnlDUEkw6ue-paA2vVRIH9oQsPo6L7jCfHEAPMgvHQVrhhtp2ROEJRBgypM1uBCb7IA6obfG5TMReQs9QOadE5/s728-rw-e365/chinesehackers.png ‘U.S. Treasury Systems’)The United States Treasury Department said it suffered a ‘major cybersecurity incident’ that allowed suspected…


  • No Holiday Season for Attackers, (Tue, Dec 31st)

    [No Holiday Season for Attackers](/forums/diary/No+Holiday+Season+for+Attackers/31552/)=======================================================================================* * [](http://www.facebook.com/sharer.php?u=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552 ‘Share on Facebook’)* [](http://twitter.com/share?text=No%20Holiday%20Season%20for%20Attackers&url=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552&via=SANS_ISC ‘Share on Twitter’) **Published** : 2024-12-31. **Last Updated** :…


  • China-Linked Salt Typhoon Hackers Launched Cyber Attack on AT&T and Verizon

    Major U.S. telecom companies AT-&T Inc. and Verizon Communications Inc. confirmed they were targeted by the China-linked hacking group known…


  • This month in security with Tony Anscombe – December 2024 edition

    VideoThis month in security with Tony Anscombe — December 2024 edition==================================================================From attacks leveraging new new zero-day exploits to a major…


  • It’s only a matter of time before LLMs jump start supply-chain attacks

    #### [Security](/security/)It’s only a matter of time before LLMs jump start supply-chain attacks======================================================================’The greatest concern is with spear phishing and…


  • Security Affairs newsletter Round 504 by Pierluigi Paganini – INTERNATIONAL EDITION

    A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free…


  • SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 26

    Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.————————————————————————————————————————————–[Now You…


  • China-linked APT Salt Typhoon breached a ninth U.S. telecommunications firm

    A White House official confirmed that China-linked threat actor Salt Typhoon breached a ninth U.S. telecommunications company.——————————————————————————————————————————A White House official…


  • 16 Chrome Extensions Hacked, Exposing Over 600,000 Users to Data Theft

    ![Chrome Extensions](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhf0TaLIhru3us2482mUHwROB8pWy907nz9LpW2rQn3K3q6PnUIOl9XTENTLnAkxohRwfUXDMup6_-wbDCzSfOUwyKG6k0vHzhj9ry_x84dL4W-hqAOoYsK1cEcRbbBO4BYhZSxCG3BhqB-RU2UfV_7tfex7ukGe4g9EzykjYfzEgmwwdhyiCNdE64ZecaK/s728-rw-e365/chrome.png ‘Chrome Extensions’)A new attack campaign has targeted known Chrome browser extensions, leading to at least 16 extensions being…